Monday, August 3, 2026

Apps & Consumer

Instructure faces new breach as hackers deface Canvas login pages

Instructure took Canvas offline after hackers defaced login pages and allegedly stole data from almost 9,000 schools, threatening to publish the information by May 12.

Instructure faces new breach as hackers deface Canvas login pages

Education technology company Instructure temporarily took its Canvas platform offline following a security incident where hackers defaced the login pages of three separate schools. Canvas, Instructure’s learning management platform for managing coursework, was targeted by a cybercrime group known as ShinyHunters. The group injected an HTML file to alter the login screens and display a message threatening to publish stolen student data on May 12 if the company does not negotiate a settlement. During the incident, Instructure’s website appeared to be partially online, at times returning a “too many requests” error, while the Canvas portal displayed a notice stating it was undergoing scheduled maintenance. According to Instructure spokesperson Brian Watkins, “out of an abundance of caution, we immediately took Canvas offline to contain access and further investigate.”

The company identified the entry point of the attack as its free tier of service. Watkins confirmed that the unauthorized actor exploited an issue related to the company’s Free-For-Teacher accounts. In response, Instructure made the decision to temporarily shut down these accounts to contain the breach. Watkins stated that disabling the Free-For-Teacher accounts gave the company the confidence to restore access to Canvas, which has since returned fully online and available for use. While the exact method used to compromise the login pages remains unclear, a member of ShinyHunters stated that this incident represents a second, separate breach.

This defacement follows a previous data breach disclosed by Instructure on Tuesday. In that earlier incident, hackers stole students’ private information, including names, personal email addresses, and messages sent between teachers and students. Following that original breach, the hackers claimed to have stolen data from almost 9,000 schools around the world. The stolen files allegedly contain information on 231 million people. The cybercrime group ShinyHunters, which claimed responsibility for the original hack, has used its leak site—a platform used to publish stolen data and pressure victims—in an effort to extort Instructure into paying a ransom to keep the data from going public. The group has compromised numerous victims over the last couple of years, following a financially motivated playbook of hacking, publicizing, and extorting.

Why it matters

The hackers are ramping up pressure on Instructure and its customers by defacing login pages after a previous data breach, hoping to force a settlement. This tactic underscores how cybercriminals are increasingly targeting user-facing interfaces to publicly leverage ransom demands against enterprise platforms.